Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC team needs to ensure that all high-severity Microsoft Sentinel incidents are automatically assigned to the senior analyst on call. The team uses Microsoft Teams for communication. Which configuration should you implement?

⚠ Common exam trap

Many candidates assume a playbook alone can handle both assignment and notification, but Microsoft Sentinel automation rules are the correct mechanism for setting incident properties like owner, while playbooks are best suited for external actions like posting to Teams.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that runs when an incident is created with severity High, sets the owner to the senior analyst, and then runs a playbook to post a message to Teams.

Automation rules in Microsoft Sentinel can directly set the incident owner when an incident is created, and then trigger a playbook to post a message to Microsoft Teams. This two-step configuration ensures high-severity incidents are automatically assigned to the senior analyst on call and the SOC team is notified via Teams without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an analytics rule to set the incident owner to the senior analyst and enable Teams integration in Sentinel settings.

    Why it's wrong here

    Analytics rules are designed to generate alerts and incidents from log queries; they do not expose actions to set an incident's owner or configuration for Teams integration. Ownership assignment is an incident state change, which only automation rules (or manual updates) can perform. Teams integration for notifications requires a playbook/Azure Logic App, not a Sentinel setting, so this option fails to meet both requirements.

  • ✗

    Create a playbook that reassigns incidents and posts to Teams, and attach it to an automation rule triggered by high-severity incidents.

    Why it's wrong here

    A playbook, built as an Azure Logic App, can post adaptive cards to Teams and run security response actions, but it cannot directly reassign incidents because incident properties like owner are managed by the Microsoft Sentinel API and automation rules. Attaching a playbook to an automation rule is the correct pattern, but the rule itself must perform the assignment step before invoking the playbook. Therefore, this answer incorrectly relies on the playbook to handle both the assignment and the notification.

  • ✗

    Create a workbook that filters high-severity incidents and configure a Teams webhook in the workbook settings.

    Why it's wrong here

    Azure Workbook is an interactive reporting canvas that visualizes analytics data from Log Analytics workspaces, not a mechanism for incident handling or permissions to update incident ownership. Workbook settings only control parameters and visualizations; they cannot subscribe to a Teams webhook to send messages. Notification to Microsoft Teams must be accomplished through a playbook triggered by an automation rule, not by a workbook filter or workbook configuration.

  • ✓

    Create an automation rule that runs when an incident is created with severity High, sets the owner to the senior analyst, and then runs a playbook to post a message to Teams.

    Why this is correct

    An automation rule can be configured to trigger 'When incident is created' and apply a condition for Severity equals High, then perform actions such as setting the owner to the senior analyst and running a playbook. The playbook, typically an Azure Logic App with a Microsoft Teams connector, can post an adaptive card message to a Teams channel. This combined approach correctly satisfies both requirements: automated ownership assignment and proactive notification, making it the right solution.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.